Turla Group, a stealthy Russia-based threat actor, may be trackable because of its penchant to use older malware and techniques. Recorded Future’s analysis showed Turla (aka Snake and Venomous Bear) to be a group that is continuing to develop its own advanced custom malware tools and adopting new attack and obfuscation methods all the time. In 2019, the group began ramping up its use of. PowerSploit and PowerStallion, all in an apparent effort to make discovery harder for defenders.”]

